Who is the data controller
The data controller for personal information collected on modenu.com is the operator of the MODENU project, contactable at [email protected]. If applicable law requires a designated representative, one will be appointed and named on this page.
Information we collect
We collect three broad categories of data:
1. Information you give us
Email address, message content and any voluntary attachments when you write to us, subscribe to a newsletter, or complete our contact form.
2. Information collected automatically
Browser type and version, operating system, referring URL, pages visited, timestamps, general geographic location derived from IP, and an anonymised device identifier used for analytics and fraud prevention. IP addresses are truncated before being written to our logs.
3. Information collected by advertising partners
Ad networks such as Google, Ezoic or Media.net may set cookies or similar identifiers to serve and measure advertising. See the Cookie Policy for the full list.
Why we collect it
- To operate the site — serving pages, load-balancing, fraud prevention, security.
- To reply to you — answering your emails and contact requests.
- To measure and improve — anonymised analytics tell us which reviews are useful and which need work.
- To fund the site — serving advertising, subject to your consent where required by law.
- To comply with legal obligations — tax, accounting, responding to lawful requests from authorities.
Legal bases (GDPR)
For readers in the European Economic Area, the United Kingdom and Switzerland, we rely on the following GDPR legal bases: consent (for non-essential cookies and marketing), legitimate interest (for site security, aggregate analytics and fraud prevention), contractual necessity (to reply to your inquiries) and legal obligation (to keep tax and accounting records).
Data sharing & processors
We share data only with vetted processors that help us run the site: our hosting provider, our email provider, our analytics provider and our advertising partners. All processors are bound by contractual privacy obligations and process data on our instructions.
We do not sell personal information. Under the CCPA, this constitutes a “do not sell” posture by default.
International transfers
Some processors are located outside your country of residence, including in the United States. Where required, transfers rely on Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism.
Retention
Contact messages are retained for up to 24 months after our last interaction with you. Analytics data is retained in aggregated, anonymised form for up to 26 months. Ad-network data is subject to each partner’s own retention rules.
Your rights
Subject to applicable law you have the right to: access your data, correct inaccurate data, delete data, restrict or object to processing, port your data, and lodge a complaint with a supervisory authority. To exercise a right, write to [email protected]. We reply within 30 days and never charge a fee unless a request is manifestly unfounded or excessive.
Children
MODENU is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us for prompt deletion.
Changes
We may update this Privacy Policy. When we do, the Last updated date at the top will change. Material changes will be highlighted at the top of the page for at least 30 days.
Security measures
Reasonable technical and organisational measures protect the personal information we collect. These include TLS encryption for all traffic, encrypted storage of contact-message attachments, restricted-access administrative dashboards protected by two-factor authentication, IP-truncation of server logs and quarterly review of processor security posture.
No system is perfectly secure. If we ever suffer a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and the appropriate supervisory authority in line with applicable law (typically within 72 hours under GDPR).
California, Virginia & other US-state rights
Residents of California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah and other US states with comparable laws have specific rights, including the right to know what information is collected, the right to delete, the right to correct and the right to opt out of the sale or sharing of personal information. As stated above, we do not sell personal information. To exercise any state-law right, write to [email protected] and identify the state you reside in.
Frequently Asked Questions
Do you sell my data?
No. We do not sell personal information. Under the CCPA and similar laws, this is our default posture.
How do I opt out of tracking cookies?
Use the consent banner shown on your first visit, or clear your browser cookies for our domain. Details are in the Cookie Policy.
How do I delete my data?
Write to [email protected] with the email address you contacted us from. We will confirm identity and delete records within 30 days.